Agentless SSH Key Investigation System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems require software agents on host computers for intrusion detection, which are resource-intensive, unreliable, and can alert intruders, while agentless solutions lack comprehensive threat detection capabilities and are resource-heavy or invasive.

Innovation Solution

An agentless investigation system that uses investigative modules to scan host computers for SSH public keys and other authentication tokens without installing software agents, minimizing resource usage and avoiding detection by intruders.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software agents are installed on host computers for security scanning, then threat detection capability is improved, but system resource consumption increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidCPU and RAM consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces a central management server as an intermediary that performs security scanning operations remotely. Instead of installing resource-intensive security agents on each host computer, the management server acts as a mediator that connects to hosts and performs scans without requiring local software installation. This resolves the contradiction by maintaining threat detection capability while eliminating the need for hosts to run resource-consuming security software.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security scanning functionality from the host computers and centralizes it on a remote management server. By removing the security agent software from the hosts and consolidating scanning operations on a central server, the system maintains comprehensive threat detection while eliminating the CPU and RAM consumption that would occur on individual host systems.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If software agents are deployed across multiple host computers, then security coverage is improved, but deployment complexity and maintenance difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoiddeployment and update complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security management system where a single management server provides security scanning services to multiple host computers. Instead of each host requiring its own dedicated security agent, the universal management server serves all hosts, simplifying deployment to just one system while maintaining comprehensive security coverage across the entire network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The central management server serves as an intermediary that handles all security operations for multiple hosts. This single intermediary point of control eliminates the complexity of managing multiple distributed agents, as all security policies, scans, and updates are coordinated through the central server rather than requiring individual configuration on each host.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If security scanning is performed continuously, then threat detection speed is improved, but host system performance degradation increases

Engineering Contradiction:
Improvethreat detection speedVSAvoidhost system performance
Core Design Contradiction:
SpeedVSProductivity

Solution Approach 1:

The patent uses the central management server as an intermediary that performs scanning operations remotely without burdening the host system resources. The management server handles all the computational workload for security scans, allowing continuous or frequent scanning to occur without impacting the productivity or performance of the monitored host computers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent moves the security scanning operation from the local dimension (host computer resources) to a remote dimension (management server resources). By performing scans from another dimensional location—the central server rather than local hosts—the system enables continuous threat detection while preserving host system performance, as the scanning workload exists in a separate computational dimension.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20240086538A1Computer investigation method and system for investigating authentication in remote host computers
Publication Date: 2024.03.14 SANDFLY SECURITY LTD
  • US20240086538A1 patent drawing
  • US20240086538A1 patent drawing
  • US20240086538A1 patent drawing

AI summary

A system and method are provided for investigating a remote host computer by using an agentless investigation system that includes a computer system with a computer processor coupled to a system memory and programmed with computer readable instructions. The method includes establishing a connection with the host computer and sending at least one agentless investigative module to the host computer. The investigative module runs on the host computer to perform at least one investigative function on the host computer. The investigative function includes an investigation of the host computer to ascertain if there are any user accounts of the host computer that have data forms including at least one authentication token in the form of an SSH public key. The investigative module is configured to locate the SSH public key and collect investigation data corresponding to the SSH public key.